American law does not ask you to obtain consent before capturing a lead. It asks you to tell people what you are doing at the moment you do it, and it forbids collection where you have not. The regulation is blunt: “If a business does not give the Notice at Collection to the consumer at or before the point of collection of their personal information, the business shall not collect personal information from the consumer.”

That is a different obligation from the European one, and companies arriving from that direction tend to build the wrong thing. They install a consent banner they may not need, and skip a notice they do need, positioned exactly where their form is.

The rules below are California’s, which matters for two reasons. They are the most developed, and they reach any business meeting the thresholds that collects information from California residents, wherever that business sits.

The structure of the obligation is worth understanding before the detail, because it explains why a cookie banner is not the answer to a form.

What the statute requires. A business controlling collection must, “at or before the point of collection”, inform consumers of the categories of personal information collected and the purposes, whether it is sold or shared, and “the length of time the business intends to retain each category”.

Why the notice exists, in the regulator’s words. To give consumers “timely notice, at or before the point of collection … so that consumers have a tool to exercise meaningful control over the business’s use of their personal information.”

And the consequence of omitting it is absolute. No notice, no collection. Not a warning, not a remediation period. The regulation says the business “shall not collect”.

The regulations address web forms specifically. A business collecting through a webform “may post a conspicuous link to the notice in close proximity to the fields in which the consumer inputs their personal information, or in close proximity to the button by which the consumer submits their personal information.”

Which locates the obligation precisely. Next to the field, or next to the button. Not in a footer, not behind a banner that appeared on arrival, not in a cookie preference centre.

One exception is worth flagging, because it is the only federal consent regime. Children’s online privacy law requires “verifiable parental consent” before collecting personal information from a child under 13. That is the exception that proves the general rule.

Notice at collection compared with a prior consent obligation on a lead capture formComparison between the notice at collection obligation applying to lead capture in the United States and the prior consent obligation applying in consent based jurisdictions, which are structurally different requirements producing different implementations. Under the American model there is no requirement to obtain permission before collecting an adult business contact’s details. The obligation is instead to inform the person at or before the point of collection of the categories of personal information being collected, the purposes for which each category is collected and used, whether each category is sold or shared, and the length of time the business intends to retain each category or the criteria used to determine that period. The stated purpose of this notice, per the regulations, is to provide consumers with timely notice at or before the point of collection so that consumers have a tool to exercise meaningful control over the business’s use of their personal information. The consequence of failing to provide the notice is absolute rather than remedial, since the regulations state that if a business does not give the notice at collection at or before the point of collection, the business shall not collect personal information from the consumer. The regulations address web forms directly, permitting the notice to be given by posting a conspicuous link in close proximity to the fields in which the consumer inputs personal information, or in close proximity to the button by which the consumer submits it, which locates the obligation at the form itself rather than in a page footer, a banner displayed on arrival, or a cookie preference centre. One federal exception exists in the form of children’s online privacy law, which requires verifiable parental consent before collecting personal information from a child under the age of thirteen, and which is the only federal regime imposing a genuine prior consent requirement.Two different obligations, two different buildsPrior consent modelAsk permission first. Without it,do not process.Produces: a banner, a preferencecentre, a consent record.Notice at collection modelTell them what you are doing, atthe moment you do it.Produces: a notice next to the fieldor the submit button.And the sanction for missing it is not a warning”If a business does not give the Notice at Collection … the business shall not collect personal information from the consumer.”Where the notice goes, per the regulation”In close proximity to the fields in which the consumer inputs their personal information, or in close proximity to thebutton by which the consumer submits” it. Not the footer. Not the banner that appeared on arrival.
The American obligation is informational and located at the form. The consequence of missing it is that collection itself is barred. Source : California Civil Code 1798.100(a) and 11 CCR 7012 (2026)

The six things the notice has to say

This is a short list, and most lead forms carry none of it.

The categories of personal information collected, written so as to give “a meaningful understanding of the information being collected”.

The purposes for which each category is collected and used.

Whether each category is sold or shared. Read the next section before answering this one, because the definitions are wider than the words suggest.

The retention period, or “the criteria used to determine the period of time it will be retained”. This is the element almost nobody has, because almost nobody has decided.

A link to the opt-out notice, if you sell or share.

A link to your privacy policy.

And one trap that voids an otherwise reasonable implementation. You may satisfy the notice with a link, but only “a link that takes the consumer directly to the specific section” containing those items. Directing them “to the beginning of the privacy policy … so that the consumer is required to scroll through other information … does not satisfy this standard.”

Which means the common pattern fails. A checkbox saying “I agree to the privacy policy” with a link to the top of that policy is not a notice at collection. An anchor link to the right section is.

Required contents of a notice at collection and the linking requirement that most implementations failThe six elements a notice at collection must contain when a business collects personal information, together with the linking requirement that determines whether a link based implementation satisfies the obligation. The first required element is a list of the categories of personal information about consumers to be collected, including categories of sensitive personal information, with each category written in a manner providing consumers a meaningful understanding of the information being collected. The second is the purposes for which those categories are collected and used. The third is whether each identified category is sold or shared. The fourth is the length of time the business intends to retain each identified category, or where that is not possible, the criteria used to determine the retention period. The fifth is a link to the notice of the right to opt out of sale or sharing, where the business sells or shares personal information. The sixth is a link to the business’s privacy policy. On implementation, the regulations permit a business collecting personal information online to give the notice by providing a link taking the consumer directly to the specific section of the privacy policy containing the six required items. However the regulations state that directing the consumer to the beginning of the privacy policy, or to another section of the privacy policy that does not contain the required information, so that the consumer is required to scroll through other information in order to determine the categories of personal information to be collected or whether the business sells or shares the information collected, does not satisfy that standard. The practical consequence is that the widespread implementation consisting of a checkbox stating agreement to the privacy policy accompanied by a link to the top of that policy does not constitute a notice at collection, whereas an anchor link resolving directly to the relevant section does.What the notice next to your form must say1Categories collected”A meaningful understanding of the information”2Purposes of collection and usePer category, not in general3Whether each is sold or sharedCheck the definitions before answering4Retention period, or the criteriaThe element almost nobody has decided5Link to the opt-out noticeIf you sell or share6Link to the privacy policyThe link trap that voids most implementations”Directing the consumer to the beginning of the privacy policy, or to another section … that does not contain therequired information, so that the consumer is required to scroll through other information … does not satisfy thisstandard.”So: an anchor link to the right section counts. “I agree to the privacy policy” with a link to the top does not.
Six items, one of which most companies have never decided. And a link to the top of your privacy policy does not count. Source : 11 CCR 7012(e) and 7012(f) (2026)

Your pixel is probably a “share”

This is the finding that changes what most B2B sites have to disclose, and it turns on two statutory definitions that are much wider than their everyday meanings.

“Sell” is not limited to money. It means disclosing personal information to a third party “for monetary or other valuable consideration.”

And “share” does not involve consideration at all. It means disclosing personal information to a third party “for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions between a business and a third party for cross-context behavioral advertising for the benefit of a business in which no money is exchanged.”

Cross-context behavioral advertising is defined too. Targeting based on information “obtained from the consumer’s activity across businesses, distinctly branded internet websites, applications, or services, other than” your own.

Put those together and the ordinary marketing stack is in scope. An advertising pixel that sends visitor data to a platform for retargeting is a disclosure to a third party for cross-context behavioural advertising. No invoice, no payment, still a share.

A state attorney general reached exactly that conclusion. In a 2022 settlement, the finding was that the company’s “arrangement with these companies constituted a sale of consumer information under the CCPA, and it triggered certain basic obligations, such as telling consumers that they are selling their information and allowing consumers to opt-out … Sephora did neither.” The penalty was $1.2 million.

Which answers element three of your notice. If you run retargeting pixels, the honest answer to “is this shared” is yes, and the opt-out obligations follow from it.

Why placing an advertising pixel constitutes sharing personal information under California lawThe statutory reasoning under which placing an ordinary advertising pixel on a business website constitutes sharing personal information, notwithstanding that no payment passes between the business and the advertising platform. Selling is defined as disclosing, disseminating, making available, transferring or otherwise communicating a consumer’s personal information to a third party for monetary or other valuable consideration, so the concept already extends beyond payment in money to any valuable consideration. Sharing is defined separately and more broadly still, as disclosing, disseminating, making available, transferring or otherwise communicating a consumer’s personal information to a third party for cross context behavioral advertising, whether or not for monetary or other valuable consideration, and the definition expressly includes transactions between a business and a third party for cross context behavioral advertising for the benefit of a business in which no money is exchanged. Cross context behavioral advertising is itself defined as the targeting of advertising to a consumer based on the consumer’s personal information obtained from the consumer’s activity across businesses, distinctly branded websites, applications or services other than the business or property with which the consumer intentionally interacts. Applying these definitions to an ordinary marketing configuration, an advertising pixel transmitting visitor data to a platform for the purpose of retargeting constitutes a disclosure to a third party for cross context behavioral advertising, and therefore constitutes sharing regardless of the absence of any invoice or payment. A state attorney general reached this conclusion in a 2022 settlement carrying one point two million dollars in penalties, finding that the retailer’s arrangement with such companies constituted a sale of consumer information triggering basic obligations to tell consumers their information was being sold and to permit them to opt out, neither of which the retailer had done.No money changes hands, and it still counts”Sell”Disclosing to a third party for”monetary or other valuableconsideration.""Share”For cross-context behavioral advertising,“whether or not for monetary or othervaluable consideration”.The definition goes further still, including transactions “for the benefit of a business in which no money is exchanged.”That clause exists to cover exactly the arrangement you have with an advertising platform.So the honest answer for a typical B2B siteIf a retargeting pixel fires, you share. That answers element three of your notice, and the opt-out duties follow.A 2022 settlement put it plainly: the arrangement “constituted a sale … and it triggered certain basic obligations,such as telling consumers that they are selling their information and allowing consumers to opt-out.” $1.2 million.
The definition was written to cover exactly this. No invoice, no payment, still a disclosure that triggers opt-out duties. Source : California Civil Code 1798.140(ad), (ah) and (k), and the 2022 Sephora settlement (2022)

The opt-out signal you have to honour

If you sell or share, a browser-level signal is not optional, and this is where recent enforcement has concentrated.

The regulator’s position. The Global Privacy Control “is one option for consumers who want to submit requests to opt-out of the sale or sharing of personal information via a user-enabled global privacy control. Under law, it must be honored by covered businesses as a valid consumer request.”

The regulation behind it. A business that sells or shares “shall process any opt-out preference signal that meets the following requirements as a valid request to opt-out of sale/sharing”, where the signal is in a commonly used format and its purpose is made clear to the consumer.

And it applies to the browser, not just the person. The signal is treated as a valid opt-out “for that browser or device and any consumer profile associated with that browser or device, including pseudonymous profiles.”

There is an upside worth knowing. The homepage “Do Not Sell or Share My Personal Information” link is not required if you honour the universal signal instead. Processing the signal properly can replace the link.

Enforcement here is real and recent. A 2025 fine of $632,500 concerned excessive verification demands before an opt-out. Another, $345,178, concerned “a failure to process consumer requests to opt out of the sale or sharing of personal information for 40 days”. A 2025 settlement of $1.55 million concerned failing to let consumers opt out of targeted advertising. And a February 2026 settlement of $2.75 million concerned “failing to fully effectuate consumers’ requests to opt-out … across all devices and streaming services.”

With one sentence worth pinning above your consent tool. From the enforcement division: “Using a consent management platform doesn’t get you off the hook for compliance.”

Enforcement outcomes concerning opt out handling under California privacy lawEnforcement outcomes concerning the handling of opt out requests under California privacy law between 2022 and 2026, each turning on the mechanics of processing opt outs rather than on the presence or absence of a consent banner. In August 2022 a cosmetics retailer settled for one point two million dollars in penalties, the attorney general finding that its arrangement with analytics and advertising companies constituted a sale of consumer information triggering obligations to tell consumers their information was being sold and to allow them to opt out, and that it failed to process user requests to opt out of sale submitted via user enabled global privacy controls. In March 2025 a motor company was fined six hundred and thirty two thousand five hundred dollars by the privacy agency over an excessive verification requirement imposed before consumers could exercise the right to opt out of sale or sharing, an asymmetric interface, and the absence of compliant contracts with advertising technology vendors. In May 2025 a clothing retailer was fined three hundred and forty five thousand one hundred and seventy eight dollars for failing to oversee and properly configure the technical infrastructure of its privacy portal, resulting in a failure to process consumer opt out requests for forty days, and for imposing identity verification before an opt out. In July 2025 a health media publisher settled for one point five five million dollars in civil penalties over failing to allow consumers to opt out of targeted advertising and sharing data with third parties without the required protections. In February 2026 an entertainment company settled for two point seven five million dollars, the largest such settlement recorded to that date, over failing to fully effectuate consumers’ requests to opt out of the sale or sharing of their data across all devices and streaming services. An enforcement official summarised the position by stating that using a consent management platform does not relieve a business of compliance responsibility.What has actually been fined2022Ad and analytics arrangement treated as a sale; opt-out signals not processed$1.2M2025Excessive verification before an opt-out; asymmetric interface$632,5002025Privacy portal misconfigured: opt-outs unprocessed for 40 days$345,1782025No way to opt out of targeted advertising; data shared without protections$1.55M2026Opt-outs not effectuated “across all devices and streaming services”$2.75MNotice what none of these are aboutA missing banner. Every one is about whether an opt-out was actually processed, end to end, across the stack.”Using a consent management platform doesn’t get you off the hook for compliance.”
Five outcomes, all about opt-out mechanics rather than about banners. The largest is the most recent. Source : California Attorney General and California Privacy Protection Agency announcements, 2022 to 2026 (2026)

What a compliant B2B lead form actually looks like

Nothing here requires a banner, a modal, or a vendor. It is page layout, settled at the same time as the rest of a B2B site designed around its lead form.

A short notice adjacent to the submit button. What you collect, why, whether it is shared, how long you keep it, and two links: one to the opt-out notice if you share, one to your privacy policy.

With the privacy policy link pointing at the section, not the top. An anchor. This is a five-minute change and it is the difference between satisfying the standard and not.

A retention answer you have actually decided. “Until you ask us to delete it” is not a period. “Three years from last contact, then deleted” is. You need one either way, because the notice has to state it.

An honest answer on sharing. If a retargeting pixel fires on the thank-you page, you share. Say so, and provide the opt-out route that follows.

A signal handler that works before the tags fire. Whatever tool you use, verify that an incoming universal opt-out signal actually suppresses the pixels rather than being recorded and ignored. That gap is what the fines above describe.

And test it yourself. Submit the form with the signal on and watch the network requests. Nobody else is going to do this, and it is the only way to know whether your stack does what your notice says.

Composition of a compliant business to business lead capture formThe composition of a lead capture form that satisfies United States notice at collection obligations, requiring no consent banner, no modal dialogue and no third party platform. The form carries a short notice positioned adjacent to the submission button stating what personal information is collected, the purposes for which it is collected, whether it is shared, how long it is retained, and providing two links, one to the opt out notice where the business shares information and one to the privacy policy. The privacy policy link must resolve to the specific section containing the required information rather than to the top of the policy, since directing a person to the beginning of the policy so that they must scroll to locate the required information does not satisfy the standard, making an anchor link the difference between compliance and non compliance. The retention statement must express an actual decided period or the criteria determining it, so that a statement such as until you ask us to delete it does not qualify whereas a statement such as three years from last contact does. The answer on sharing must be honest, so that where a retargeting pixel fires on a confirmation page the business shares and must say so and provide the corresponding opt out route. Behind the page, the business must ensure that an incoming universal opt out preference signal actually suppresses the advertising tags rather than being recorded and disregarded, since the gap between a recorded signal and a suppressed tag is what recent enforcement actions have concerned. The verification step is for the business to submit a test lead with the signal enabled while observing outbound network requests, since if the advertising tags still fire the notice is describing a system the business does not operate.What to put next to the buttonWhat we collect: your name, work email and company.Why: to send you the guide and to contact you about our services.Shared: yes, with advertising platforms for retargeting.Kept for: three years from your last contact with us, then deleted.Opt out of sharing · Privacy policy, collection sectionSix lines. Each one maps to a required element. Both links are anchors, not homepage links.And the test nobody runsTurn on a universal opt-out signal, submit the form, and watch whether the advertising tags still fire.If they do, your notice describes a system you do not have. That gap is what the fines have all been about.
No banner, no modal, no vendor. Six lines next to the button, and one test you run yourself. Source : Method, over 11 CCR 7012 and the CCPA opt-out provisions (2026)

What to do with this

Take one landing page and read it as a regulator would. Is there a notice within sight of the button? Does its link land on the right section? Does it state a retention period? Does it admit that you share?

Then check the thing behind the page. Turn on a universal opt-out signal, submit a test lead, and watch whether the advertising tags still fire. If they do, your notice is describing a system you do not have.

Neither of those tasks needs a lawyer or a platform. They need an afternoon, and they close the gap that every recent enforcement action has been about.

The adjacent pieces are what US law requires on a B2B website and customer data before you have a CRM.